Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Yaws < 1.80 - Multiple Headers Remote Denial of Service Vulnerabilities
CVE-2009-0751dosmultiple
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with
28RISK
open
ReferênciaVexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
CVE-2006-4584webappsphp
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and passwo
23RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.07 - 'imgsrc' Remote Buffer Overflow
CVE-2008-3583remotewindows
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long UR
23RISK
open
ReferênciaVexDay Proof
WikkiTikkiTavi 1.11 - Arbitrary '.PHP' File Upload
CVE-2009-0602webappsphp
Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
MLdonkey 2.9.7 - Arbitrary File Disclosure
CVE-2009-0753remotemultiple
Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files vi
23RISK
open
ReferênciaVexDay Proof
Rising AntiVirus Online Scanner - Insecure Method Flaw
CVE-2008-1116remotewindows
Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner all
28RISK
open
ReferênciaVexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3591webappsphp
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attack
23RISK
open
ReferênciaVexDay Proof
events Calendar 1.1 - Remote File Inclusion
CVE-2008-4673webappsphp
PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Ca
23RISK
open
ReferênciaVexDay Proof
PHP-Ring Webring System 0.9.1 - Insecure Cookie Handling
CVE-2008-3602webappsphp
admin/wr_admin.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9.1 allows remote attackers to bypass authentica
23RISK
open
ReferênciaVexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
CVE-2009-0765webappsphp
Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary l
23RISK
open
ReferênciaVexDay Proof
b1gbb 2.24.0 - SQL Injection / Cross-Site Scripting
CVE-2007-3590webappsphp
Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
YapBB 1.2 - 'forumID' Blind SQL Injection
CVE-2009-0768webappsphp
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
webSPELL 4.2.0e - 'page' Blind SQL Injection
CVE-2009-1912webappsphp
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
fresh email script 1.0 - Multiple Vulnerabilities
CVE-2008-7043webappsphp
Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remo
23RISK
open
ReferênciaVexDay Proof
PPC Search Engine 1.61 - 'INC' Multiple Remote File Inclusions
CVE-2007-0167webappsphp
Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow
28RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2158webappsphp
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes
23RISK
open
ReferênciaVexDay Proof
PHPBasket - 'pro_id' SQL Injection
CVE-2008-3713webappsphp
SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
CVE-2006-4589webappsphp
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RISK
open
ReferênciaVexDay Proof
Hex Workshop 6.0 - '.hex' Local Code Execution
CVE-2009-0812localwindows
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions all
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6500webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete
23RISK
open
ReferênciaVexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
CVE-2008-3734doswindows
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP serv
28RISK
open
ReferênciaVexDay Proof
Imera ImeraIEPlugin - ActiveX Control Remote Code Execution
CVE-2009-0813remotewindows
Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Clien
23RISK
open
ReferênciaVexDay Proof
Hewlett Packard 1.0.0.309 - 'hpqvwocx.dll' ActiveX Magview Overflow (PoC)
CVE-2007-2656doswindows
Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote
23RISK
open
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUnifiedControl.dll 1.1.45.0' - 'SetText()' Command Execution
CVE-2007-4582remotewindows
Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Netwo
23RISK
open
ReferênciaVexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3779webappsphp
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
Sponge News 2.2 - 'sndir' Remote File Inclusion
CVE-2006-4647webappsphp
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Mambo Component CopperminePhotoGalery - Remote File Inclusion
CVE-2006-4321webappsphp
PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier f
23RISK
open
ReferênciaVexDay Proof
z-breaknews 2.0 - 'single.php' SQL Injection
CVE-2008-3848webappsphp
SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
SFS Ez Forum - SQL Injection
CVE-2008-4754webappsphp
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
PollHelper - Remote Configuration File Disclosure
CVE-2009-0827webappsphp
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to downloa
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.